Hosting · All systems operational Melbourne time AEDT

Website audits

  • Search & AI visibility

    A look at how well your site can be read, ranked, and cited, both by Google and by the AI tools people now ask instead of searching, like ChatGPT, Perplexity, and Google’s own AI answers. Under the hood it’s the same work: clean structure, good metadata, schema, and content that answers a question clearly. Google calls it Search Engine Optimisation. Making a site easy for search engines like Google to read, understand, and rank.. The AI version gets called Answer Engine Optimisation. The same idea aimed at AI answer tools, so they can read and cite your site directly. or Generative Engine Optimisation. Helping generative AI like ChatGPT surface and quote your content. Much the same work as AEO.. It all lives on the page.

    What’s included

    Why it matters. How people find sites is shifting. Plenty still use Google, but more of them now ask an AI and take the answer it gives. Both rely on the same thing, a site that’s well structured and easy to understand. This audit covers that on-page side, the parts built into your own site.

    • On-page and technical SEO
    • Title tags, meta descriptions, and headings
    • Structured data and schema markup
    • Semantic HTML and content structure
    • Internal linking and site structure
    • Crawlability: robots, sitemaps, indexing
    • Canonical tags and duplicate content
    • Content clarity and answerability for AI (AEO / GEO)
    • Open Graph and share metadata

    This is on-page and technical work, the things that live on your own site. It doesn’t cover keyword research, link building, or running an ongoing SEO or ad campaign. If that’s what you need, a specialist SEO agency is the better fit, and we’ll say so.

  • Performance

    A look at how fast your site really loads, and what’s slowing it down. We measure the things Google measures, the Core Web Vitals, and trace each one back to its cause, whether that’s heavy images, bloated code, or slow hosting.

    What’s included

    Why it matters. A slow site loses people before they’ve seen it, and Google ranks slow pages lower. Usually a handful of fixable problems are doing most of the damage. The audit finds them, and tells you which ones are worth your time first.

    • Core Web Vitals: LCP, INP, CLS
    • Total load time and time to first byte
    • What delays the largest content paint
    • Image sizing, formats, and compression
    • Render-blocking CSS and JavaScript
    • Browser and server caching
    • Font loading and layout shift
    • Third-party scripts and what they cost
    • Performance on mobile, not just desktop
  • Accessibility

    A check of whether your site works for everyone, including people using a keyboard, a screen reader, or larger text. We test it against Web Content Accessibility Guidelines. The international standard for accessible websites, with three levels: A, AA, and AAA. Most organisations aim for AA., the international standard for accessible websites, at whichever level you need to meet.

    What’s included

    Why it matters. About one in five people has a disability of some kind, and a site they can’t use is a customer lost. For many Australian organisations it’s also a legal expectation, not just a nicety. The audit shows you where the site falls short, and what to fix first, in plain terms.

    • WCAG 2.2, at the level you need (A, AA, or AAA)
    • Keyboard navigation and focus order
    • Screen-reader labelling and landmarks
    • Colour contrast and text sizing
    • Headings and document structure
    • Form labels, errors, and instructions
    • Image alt text, and decorative images
    • Link and button names
    • Reduced-motion and animation safety
  • Analytics & tracking

    A check of whether the numbers you’re reading are real. We follow each event from the page through to the report: what fires, what fires twice, what quietly stopped months ago, and whether consent is being handled the way it has to be.

    What’s included

    Why it matters. Most sites are measuring something wrong, and nobody finds out until a decision gets made on the number. Duplicate tags inflate traffic, a broken conversion hides sales, and consent set up badly means whole groups of visitors never get counted at all. Better to know that before you act on a report, not after.

    • GA4 receiving data, and set up sensibly
    • Events and conversions: firing, once, with the right values
    • Duplicate, orphaned, and long-dead tags
    • Google Tag Manager container structure
    • Cookie banner and Consent Mode v2 behaviour
    • Server-side tracking, where it is in use
    • Cross-domain and subdomain tracking
    • E-commerce data: purchases, revenue, refunds
    • Search Console verified, linked, and reporting
    • Bot and internal traffic filtering

    This checks that your tracking is accurate, not what the numbers say. Reading the data and deciding what to act on is a separate piece of work, usually done by whoever runs your marketing, and the audit makes sure they’re working from numbers they can trust.

  • Security

    A look at how the site is built and kept, and where that leaves it exposed. Which software versions are running, what’s no longer maintained, who still has an account and what they can do, how logins are protected, and whether the backups would actually restore.

    What’s included

    Why it matters. Most sites that get broken into were never targeted. They were running software with a known hole in it, or an admin account nobody had switched off. The audit finds those, tells you which ones are worth acting on first, and confirms whether you could get the site back if the worst happened.

    • Platform, plugin, and extension versions
    • Software with known vulnerabilities, and anything no longer maintained
    • User accounts, roles, and admin access nobody uses
    • Login protection: two-factor, rate limiting, exposed endpoints
    • File permissions, and file editing from the admin panel
    • SSL certificate, renewal, and security headers
    • Backups: what runs, where it lands, and a test restore on a copy
    • Malware and injected-content scan
    • Server-level protection: firewall, DDoS, virtual patching

    This is a review of how the site is set up and maintained. It isn’t penetration testing, and it isn’t a forensic investigation of a site that’s already been broken into.

  • Infrastructure

    A map of everything the site quietly depends on, and who controls each piece. Where the domain is registered, where DNS points, what the hosting is, which services are wired in, and which licences are keeping features alive. It’s all written down in one place, often for the first time.

    What’s included

    Why it matters. This is the audit nobody asks for until it bites. A domain renewal notice going to someone who left two years ago. A licence lapsing, so a plugin stops getting updates. DNS nobody can change because the login went with the last developer. The audit writes it all down, and makes sure you can get to every piece when you need it.

    • Domain registration, renewal dates, and who controls the account
    • DNS records, and where each one actually points
    • Hosting: plan, server software versions, resource headroom
    • Email records: SPF, DKIM, DMARC present and pointing the right way
    • CDN, caching, and firewall layers
    • SSL certificates, and how they renew
    • Software licences: cost, renewal, whose account
    • Third-party services, and who owns each one
    • Backups: what they cover, and where they live
    • Monitoring, error logging, and who gets told

    The audit documents what you have and what needs tidying. Moving domains, transferring accounts, and sorting out licences is separate work, and we’re happy to quote for it once the audit is done.

  • Something else? Tell us what’s worrying you, and we’ll say whether an audit is the right answer and what it would cost.

How it works

Every audit follows the same steps, and your site stays exactly as it is while we work.

  1. Tell us about the site

    The address and a line about what prompted it: traffic dropped, a slow checkout, a security scare. That’s enough to start.

  2. Fixed quote

    A price, what it covers, and when to expect the report. Nothing starts until you say yes.

  3. Access

    Usually just the address. Some audits need more, like read access to Search Console or analytics, or a temporary login for a security audit. We’ll say exactly what, and why.

  4. The audit

    We run the checks with specialist tools and go through every result ourselves, so the report only includes what matters for your site. We only look: nothing gets changed.

  5. The report

    Findings in priority order, in plain English: what we found, why it matters, how to fix it, and how urgent it is. A summary up top, detail below for whoever does the work.

  6. A call

    Half an hour to walk through the findings and answer your questions, if you’d like one. There’s no obligation to have us do any of the work.

  7. The fixes

    Your developer, your agency, or us. If you’d like us to do them, we’ll quote separately. The report is yours either way.

Want to know where your site stands?

Fill in the blank and send. Tell us about the site and we’ll scope the audit and come back with a fixed quote.

Send us a message

To Chris Anderson <chris@brightspire.com.au>

We’d like for our website.